Candid Health
Security Engineer
Part remote, part office, you need to live within commuting distance of a named location.
Hybrid · New York City
Employer listed it 8 weeks ago · Added yesterday
Been open since 8 weeks ago. Long-running listings are sometimes left up after the role is filled.
Salary
$180k to $258k per year
Location
Hybrid · New York City
Timezone
Not stated
Contract
Full-time
Experience
Mid
Category
Software
Stated by the employer in the job description
Remote flexibility
Hybrid
This role is only partly remote, the employer expects time in the office around New York City, Denver, San Francisco, Hybrid, so you need to live within commuting distance.
What the employer says
- Source listing states candidate location: "New York City, Denver, San Francisco, Hybrid"
- Listing mentions "Hybrid"
What Nomaders makes of it
- Not suitable if you plan to move between countries
The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.
About the role
What we do
We’re fixing one of the most broken and costly pieces of the US healthcare system: medical billing.
Today, healthcare providers spend over $250B each year on administrative overhead just to get paid by insurance. Medical billing is expensive because it’s nuanced and hard - maybe ~100x harder than credit card payment processing - and because it’s traditionally done by armies of humans who track and manage complex rules and processes specific to individual insurance companies with little or no supporting software. We’re rethinking medical billing from the ground up, building software backed by best-in-class data science (and, soon, a dash of machine learning) to automate much of this complexity so healthcare providers can get paid dramatically more easily and inexpensively.
We were in the Y Combinator W20 batch and have since been well funded by a world-class group of funds (8VC, First Round Capital, BoxGroup) + angel investors. We're now helping our customers treat opioid addiction, provide holistic care for women, lose weight, increase access to mental health care, and much more. This is such important and gratifying work; we can't wait for you to join our team and help support some of the most important innovation happening in healthcare today!
Curious to learn more about our story? Check out this blog post written by our founders.
The Role
We're looking for a Senior Security Engineer who is ready to elevate the safety and security of our systems and networks. You will serve as our guardian, ensuring our platforms are resilient against all threats while meeting compliance requirements. We value a hands-on approach and seek someone who is conversant with the nitty-gritty of security frameworks, while being deeply engaged in strategic and operational security endeavors.
What You’ll Do
Build Security Guardrails: Build security protections into our systems to ensure a secure by default posture.
Collaborate with Engineering Teams: Participate in design reviews and threat modeling sessions to identify potential security flaws early in the development process, and validate the security of new features and services during rollout ensuring security remains at the forefront of all initiatives.
Implement & Navigate Compliance Rituals: Understand, oversee, and drive the rituals associated with HIPAA, SOC2, SOC1, PCI and HITRUST to ensure that we remain compliant and informed.
Vulnerability Management: Regularly audit our platforms and tech stack for vulnerabilities, ensuring that vulnerabilities are identified and addressed in a timely manner.
Manage Third-party Relationships: Coordinate with vendors for penetration testing and other security services, ensuring that our platforms undergo regular scrutiny and remain fortified, review vendor security prior to integration .
Who You Are
You have 4+ years of experience in the security domain, with a proven track record of hands-on involvement in complex projects.
Your expertise isn't just theoretical. You know how to "talk the talk", especially when it comes to the rituals and routines of security compliance.
With strong knowledge of HIPAA, you're no stranger to the delicate information we handle.
You are adaptable and flexible, always ready to engage with security challenges at both enterprise and client levels.
You write code to automate security, you possess the ability to read, understand, and audit systems, networks, and IT setups to ensure airtight security.
Our values
We spend at least as much time with our coworkers as we do with our closest friends + family - if we intend to do the most important + challenging work of our lives, it’s important that these folks energize us, support us, inspire us, and push us to do our best work. This is what you can expect of your teammates at Candid (in no particular order):
We put our customers first
We take care of each other and ourselves
We anchor on outcomes and work relentlessly and creatively to achieve them
Requirements
The employer hasn't listed requirements separately, they're described in the role summary above and on the original listing.
Benefits
No benefits package published with this listing. Ask about it at first interview.
How to apply
- 1Check the flexibility label above, hybrid, matches where you plan to live and work.
- 2Tailor your CV to the role at Candid Health, mentioning your remote working experience.
- 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.
Found 1d ago. Last checked 23 Sept. Always confirm the details on the original posting, salary and location can change after publication.
Listing sourced from Company boards.
Similar roles
Other open software roles with comparable remote rules.
Free to apply, no account needed.
$180k to $258k per year · You'll be taken to the employer's careers page.